cbcvebase.
CVE-2009-2416
published 2009-08-11

CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a…

PriorityP421medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.81%
76.1th percentile
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
appleiphone_os>= 2.0 < 4.04.0
applemac_os_x< 10.4.1110.4.11
applemac_os_x>= 10.5.0 < 10.5.810.5.8
applemac_os_x>= 10.6.0 < 10.6.210.6.2
applemac_os_x_server< 10.4.1110.4.11
applemac_os_x_server>= 10.5.0 < 10.5.810.5.8
applemac_os_x_server>= 10.6.0 < 10.6.210.6.2
applesafari< 4.0.44.0.4
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibxml2< libxml2 2.7.3.dfsg-2.1 (bookworm)libxml2 2.7.3.dfsg-2.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
googlechrome< 2.0.172.432.0.172.43
opensuseopensuse10.3 – 11.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
sunopenoffice.org>= 2.0.0 < 2.4.32.4.3
sunopenoffice.org>= 3.0.0 < 3.1.13.1.1
suselinux_enterprise
suselinux_enterprise

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.